Skip to content
Automation Squad
Hands holding a blank sheet of cream paper to the window, a faint starburst watermark in the fibres
Policy·2 min read·By the Automation Squad Research

Claude Now Watermarks Its Text Worldwide

Nothing you are doing becomes wrong today. But you should know which of your work now carries a mark.

Robert MacKelfresh

By Robert MacKelfresh

Founder, Automation Squad ·

The short answer

Claude's text output now carries a statistical watermark, applied worldwide, created by biasing word choice with a private key. It survives copy-paste, light editing and translation. Only a complete rewrite removes it. It is unreliable on short text, fact-dense passages and code, and no public detection tool exists yet.

Survival table

What the watermark survives, and the three-bucket sort for work you've shipped

The table is the reference. The sort underneath it is the ten-minute pass that tells you whether you need to disclose anything.

  1. List the last few things you shipped with Claude's help

    Client deliverables, published posts, graded work, anything with your name on it. You are looking for the last month or so, not your whole history.

  2. Sort each one into three buckets

    A — Claude wrote it. B — Claude edited my draft. C — I wrote it, Claude only advised. The watermark cannot tell A from B, which is exactly why you need to know which is which.

  3. Check what your contracts, employer policy or course rules actually say

    Look for a disclosure clause on AI use. Bucket A triggers most of them. Bucket C almost never does. Bucket B is the argument you want evidence for.

  4. Keep the version history on anything in bucket B

    A drafting trail is the only thing that separates 'edited with AI' from 'generated by AI' once a detector says the text is marked. Google Docs history, git, or dated drafts all work.

  5. Disclose now if a rule requires it, rather than after a detector does

    Volunteering it costs a sentence. Being asked about it later costs the benefit of the doubt.

SituationWatermark
Copy and pasteSurvives
Light editingSurvives
Translation produced by ClaudeSurvives
Complete rewrite, every word replacedRemoved
Short samplesUnreliable
Fact-dense passages with forced termsUnreliable
CodeGenerally weaker
Images and filesC2PA metadata, not a watermark
Public detection APIPromised, not shipped

Take it with you

CLAUDE WATERMARK — what it means for work I've shipped
Source: https://automationsquad.com/news/claude-text-watermark-explained/

SURVIVES:   copy-paste · light editing · translation by Claude
REMOVED BY: a complete rewrite where every word is replaced
UNRELIABLE: short samples · fact-dense passages · code
IMAGES:     C2PA metadata instead (nothing inside the file changes)
DETECTION:  a public API is promised but not shipped yet
SCOPE:      applied globally, on models from Aug 2 2026; older models
            being backfilled "over the coming months"

THE THREE-BUCKET SORT
  A — Claude wrote it
  B — Claude edited my draft
  C — I wrote it, Claude only advised

The watermark CANNOT distinguish A from B. A detector hit is evidence of
involvement, not of authorship.

[ ] Sort my last few shipped pieces into A / B / C
[ ] Check contracts / employer policy / course rules for a disclosure clause
[ ] Bucket A: disclose if any rule requires it
[ ] Bucket B: keep the version history — it's the only proof of what I did
[ ] Bucket C: no action

Anthropic published its explainer on Claude text watermarking on August 14, 2026. The technique biases the model's word selection using a private key, leaving a statistical signature that a detector holding that key can find later.

The facts, from Anthropic's own post: watermarking applies to future Claude models, and Anthropic says it is "working to add watermarking" for models launched before August 2, 2026, rolled out over the coming months. It is applied globally, and Anthropic is explicit about why — "we don't yet have a durable way to scope it by region." It survives light editing and translation; a Claude-produced translation is watermarked because every word in it was chosen by Claude. A complete rewrite in which every word is replaced removes it. Anthropic names its own limits: the watermark is weak on short samples, weak on fact-dense passages where specific terms are forced, and generally weaker in code, which often has to be exact. A public detection API is promised but not yet shipped. Files get C2PA content credentials instead, which Anthropic notes are metadata — nothing inside the file changes.

Automation Squad's take: read the limits carefully, because they cut both ways. The watermark cannot tell the difference between Claude writing something from nothing and Claude heavily editing your draft — so a detector hit is not evidence of authorship, it is evidence of involvement. That distinction is going to be lost by roughly everyone the first time a university or a client runs a check, and the burden of explaining it will land on the writer. The practical response is not to avoid Claude; it is to keep the drafting history that shows what you actually did. Anyone publishing under a byline, submitting graded work, or delivering copy under a contract that speaks to AI use should know this changed, and should know that no public detector exists yet to check their own work against.

Run this now: pick the last three pieces of writing you shipped with Claude's help and sort them into three buckets — Claude wrote it, Claude edited mine, I wrote it and Claude only advised. Then check whether any client contract, employer policy, or course rule you are bound by has a disclosure clause that the first bucket triggers. If it does, disclose it now rather than after a detector does it for you. Keep your version history on anything in bucket two; a drafting trail is the only thing that separates "edited with AI" from "generated by AI" once the detection API ships.

By the numbers

The data behind the story — figures from cited sources, with our own analysis labelled.

What the watermark does and does not survivePer Anthropic — How Claude's text watermarking works
Copy and pasteSurvives
Light editingSurvives
Translation by ClaudeSurvives
Complete rewrite, every word replacedRemoved
Short samplesUnreliable
Fact-dense passages with forced termsUnreliable
CodeGenerally weaker
Images and filesC2PA metadata, not a watermark
Public detection APIPromised, not shipped

Anthropic publishes these limits itself. The short-text and code weaknesses matter as much as the survival claims.

Questions people are asking

Does the Claude watermark survive copy and paste?
Yes. It survives copy-paste, light editing, and translation — a Claude-produced translation is watermarked because every word in it was chosen by Claude. Only a complete rewrite in which every word is replaced removes it.
Can I check whether my own text is watermarked?
Not yet. Anthropic says it will offer a watermark detection API and is working out the implementation, but nothing public has shipped. Until it does, you cannot verify your own work either way.
Does the watermark prove Claude wrote something?
No, and this is the distinction most likely to be lost. Anthropic states the watermark cannot distinguish between Claude writing original content and Claude heavily editing existing text. A detection hit is evidence of involvement, not of authorship — which is why keeping your drafting history matters.
Does watermarking apply outside the EU?
Yes. Anthropic applies it globally at launch, and is explicit about why: it does not yet have a durable way to scope watermarking by region.
Is code watermarked too?
Less reliably. Anthropic notes that code, which in many cases has to be exact, generally carries less watermarking than other forms of text — the technique works by biasing word choice, and code leaves far less room for that.

Last checked August 15, 2026 against the primary sources above, by Automation Squad Research. Spot an error? [email protected].

Related artifacts

More news